Network

malanden

New Member
May 25, 2026
6
1
3
I am clearly doing something dumb, and just have not figured it out
My proxmox server is at a local DC
It is connected to my home router via Route Based IPSEC
From the CLI of the Proxmox server, I can ping any host on my home subnet, no issues
From home subnet I can access any proxmox VM with no issues, including my windows server 2025 VM

The problem is, when I try to go the other way
I cannot ping or connect from ANY proxmox VM to my home subnet
Proxmox CLI just fine
Actual VMs, nope.

PROXMOX PING:
PING 192.168.2.1 (192.168.2.1) 56(84) bytes of data.
64 bytes from 192.168.2.1: icmp_seq=1 ttl=63 time=3.61 ms
64 bytes from 192.168.2.1: icmp_seq=2 ttl=63 time=3.65 ms
64 bytes from 192.168.2.1: icmp_seq=3 ttl=63 time=3.38 ms

Proxmox TRACEROUTE
traceroute to 192.168.2.97 (192.168.2.97), 30 hops max, 60 byte packets
1 sophos.********.ca (192.168.1.1) 0.470 ms 0.408 ms 0.375 ms
2 * * *
3 192.168.2.97 (192.168.2.97) 3.899 ms 4.139 ms 3.870 ms
root@pve:~#

Windows Server 2025 VM CMD Prompt
Pinging 192.168.2.97 with 32 bytes of data:
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.
Reply from 192.168.1.1: Destination host unreachable.

Ping statistics for 192.168.2.97:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),

Ubuntu VM
PING 192.168.2.79 (192.168.2.79) 56(84) bytes of data.
From 192.168.1.1 icmp_seq=1 Destination Host Unreachable
From 192.168.1.1 icmp_seq=2 Destination Host Unreachable
From 192.168.1.1 icmp_seq=3 Destination Host Unreachable

1790883130044.png
 
Here you go
And like I said, from the PVE Host command line, I can ping the 192.168.2.0/24 network anywhere, but NOT from any VM running on PVE
auto lo
iface lo inet loopback

iface eno2 inet manual

iface eno3 inet manual

iface eno4 inet manual

iface eno1 inet manual

iface enp134s0f0 inet manual

iface enp134s0f1 inet manual

iface enx803f5dd61ab2 inet manual

iface enp129s0 inet manual

auto vmbr0
iface vmbr0 inet static
address 192.168.1.14/24
gateway 192.168.1.1
bridge-ports eno1
bridge-stp off
bridge-fd 0

source /etc/network/interfaces.d/*
 
Your /etc/network/interfaces looks fine, and I would not add any routes there. The key clue is that the VMs get “Destination Host Unreachable” from 192.168.1.1, which likely means their traffic is reaching the Sophos and being rejected or misrouted there. Since the Proxmox host can reach the home subnet and the home subnet can reach the VMs, I’d focus entirely on the Sophos firewall/VPN routing rules. I am not a Sophos user, so I can't advise you there but my guess is you need to add a firewall rule to allow the traffic in the opposite direction.
 
Thats what I cannot understand. Proxmox and the VMS share the same subnet. So if proxmox at 192.168.1.14 can ping and get through to 192.168.2.1, a windows VM with 192.168.1.12 and Ubuntu VM with 192.168.1.24 shouldn't have any issue either I would think. Maybe I have a NAT or something in the way. Thanks for the advice
 
My understanding of Sophos is you need to have a firewall rule allowing access in each direction. So you need at least two rules